CVE-2026-25897: ImageMagick has heap overflow in sun decoder on 32-bit systems that can result in out of bounds write
An Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write.
================================================================= ==1967675==ERROR: AddressSanitizer: heap-buffer-overflow on address 0xf190b50e at pc 0x5eae8777 bp 0xffb0fdd8 sp 0xffb0fdd0 WRITE of size 1 at 0xf190b50e thread T0
Other sources
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25897?
CVE-2026-25897 is classified as a critical vulnerability due to its potential for heap overflow and out-of-bounds writes on 32-bit systems.
How do I fix CVE-2026-25897?
To fix CVE-2026-25897, upgrade ImageMagick to version 7.1.2-15 or 6.9.13-40 or later.
Which versions of ImageMagick are affected by CVE-2026-25897?
CVE-2026-25897 affects versions of ImageMagick prior to 7.1.2-15 and 6.9.13-40.
What systems are primarily impacted by CVE-2026-25897?
CVE-2026-25897 primarily impacts 32-bit systems when processing specially crafted images.
Is there a workaround for CVE-2026-25897?
Currently, the recommended workaround for CVE-2026-25897 is to upgrade to a non-vulnerable version of ImageMagick.